The First MCP Lawsuit: Runlayer v. Rippling Signals a Maturing Agent Economy

Share:
On July 28, 2026 Runlayer sued Rippling in the Southern District of New York, alleging Rippling misappropriated trade secrets and cloned its MCP gateway after a nearly year-long trial under NDA; Runlayer, backed by Khosla Ventures and Felicis, suspended services on June 12, retained Sullivan & Cromwell led by former USPTO director Andrei Iancu, and is seeking a preliminary injunction and damages. Rippling denies the claims and is launching its own MCP gateway, and the dispute — coming as the MCP stateless protocol spec was finalized — raises security, IP and adoption risks for protocol implementations and could set a precedent for how proprietary gateway architectures are protected within open standards.
Runlayer’s July 28, 2026, lawsuit against Rippling in the Southern District of New York marks the first intellectual property dispute within the Model Context Protocol (MCP) ecosystem. This legal action confirms that MCP has moved beyond its origins as a collaborative protocol experiment into a contested commercial category. By litigating the ownership of gateway architectures, the parties have signaled that the underlying infrastructure now holds sufficient market value to warrant formal court intervention, effectively tempering open-source idealism with the pressures of enterprise competition.
At the center of the dispute is the MCP gateway—a centralized control plane that sits between AI agents and MCP servers to manage critical enterprise functions like authentication, access control, observability, and policy enforcement. Runlayer, a startup backed by Khosla Ventures and Felicis, alleges in a complaint reported by TechCrunch that Rippling misappropriated its trade secrets after a nearly year-long product trial. According to the complaint, the two companies operated under a mutual non-disclosure agreement (NDA) and a trial agreement that explicitly prohibited Rippling from copying Runlayer’s intellectual property or creating derivative works. Runlayer claims that during this period, it shared its product roadmap, source code, and specific gateway deployment architecture with Rippling.
The tension escalated after price negotiations for a long-term commercial deal collapsed. Runlayer suspended its services to Rippling on June 12, 2026. The complaint alleges that on that same day, a Rippling insider sent a text message to Runlayer CEO Andrew Berman stating that there was \u201ca project internally to build essentially a clone of Runlayer \u2026 it’s almost a 1 to 1 copy of Runlayer.\u201d Runlayer further alleges that on July 1, it received an unsolicited screenshot of what it claims is Rippling’s competing gateway product.
The legal firepower involved underscores the perceived stakes of this litigation. Runlayer has retained Sullivan & Cromwell, with the team led by Andrei Iancu, the former Director of the United States Patent and Trademark Office. By deploying a former USPTO head, Runlayer is signaling that this is not merely a contract dispute, but a foundational argument over the protectability of agentic infrastructure. Runlayer is seeking a preliminary injunction to block Rippling from developing or selling the allegedly derived product, alongside monetary damages.
Rippling has confirmed it is launching its own MCP gateway but has categorically denied the allegations of misappropriation. A spokesperson for the company characterized the lawsuit as follows: \u201cRunlayer\u2019s panicked effort to avoid competition by fabricating claims is not an effective way to deal with its business failures. Rippling is launching a superior product for connecting AI tools to business data using only our proprietary information \u2014 we have every reason to win in this market.\u201d This defense follows a standard pattern in trade secret litigation, where the defendant argues that the resulting product was built independently through legitimate means rather than through the misuse of confidential information.
This lawsuit arrives at a pivotal moment for the MCP ecosystem. The protocol recently finalized its stateless specification, and as enterprise procurement teams begin to include MCP compliance in their security baselines, the pressure to ship robust, secure gateways has intensified. The industry has already seen architectural lock-in begin to take hold, and this legal action represents the point where commercial pressure finally takes a formal legal shape. The security debt inherent in early agent deployments is now being addressed by enterprise-grade gateways, making these components the most valuable real estate in the agent stack.
The core question left for the industry is what \u201cowning\u201d an MCP gateway architecture actually means when the underlying protocol is open. As other enterprise players like Snowflake and AWS ship their own gateway products, the line between standard protocol implementation and proprietary trade secret will be tested. If the courts find that specific deployment architectures can be protected despite the open nature of the protocol, it could fundamentally alter how developers approach building on top of MCP. For now, the industry is watching to see if this case establishes a precedent for how proprietary value is extracted from open standards.
Related:
The finalization of the MCP stateless specification
MCP security debt as an architectural choice
Architectural lock-in in the MCP ecosystem





